Overview The Dossier Protocols About Commission a brief
Legal

Privacy Policy

How The Advance Brief collects, uses and protects the personal information of travellers and clients.

Effective July 2026. We may update this from time to time; the current version is always the one posted here.

The Advance Brief, a registered sole proprietorship in Ontario (Business Identification Number 1001666858) ("we", "us"), prepares pre-travel intelligence dossiers. We take the privacy of travellers and clients seriously. This Policy explains what personal information we collect, why, how we protect it, who we share it with, and the rights available to you.

1. Who we are and scope

We are the organisation responsible for (the "controller" of) the personal information described here. This Policy covers information we process to provide our Services. Our privacy practices are governed by Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). Where we serve travellers in the European Union or United Kingdom, we also apply the EU/UK GDPR; where we serve California or other US residents, applicable US state privacy laws may also apply.

2. Personal information we collect

To prepare a dossier we typically collect, from the client organisation and/or the traveller:

Some of this may be sensitive information, for example information that could reveal health needs. Under the GDPR, such "special category" data requires explicit consent or another Article 9 condition; we collect it only where necessary for the dossier and where that basis is met.

3. Sources

We collect personal information directly from the traveller and from the client organisation that engages us. We also compile non-personal destination intelligence from public and official sources, such as government advisories. That destination material is not personal information about the traveller.

4. Why we use it and our legal bases

PurposePIPEDA basisGDPR / UK basis (where applicable)
Prepare and deliver the dossier and emergency cardConsent; necessary for the service requestedArt. 6(1)(b) performance of a contract
Communicate with the client or traveller about the engagementConsent; reasonable purposeArt. 6(1)(b); 6(1)(f) legitimate interests
Include sensitive or health-related details the client asks us to addExpress consentArt. 9(2)(a) explicit consent
Keep records, invoice, and meet legal and accounting dutiesReasonable purpose; legal requirementArt. 6(1)(c) legal obligation; 6(1)(f)
Protect vital interests in an emergency, if neededConsent; emergency exceptionArt. 6(1)(d) vital interests

We identify these purposes at or before collection and limit collection to what is necessary for them.

5. Who we share it with

We do not sell personal information. We share it only as needed to deliver the Services:

A current list of sub-processors is available on request.

6. International transfers and storage

We are based in Canada and store information in Canada and/or the location of our cloud provider. Providing our Services may involve transferring information across borders, for example itinerary details about travel to the US or EU/UK, or storage with a provider located outside your country. Where we transfer personal information of EU/UK individuals outside their region, we rely on an appropriate safeguard such as the Standard Contractual Clauses, the UK IDTA, or an adequacy decision. [Storage locations and transfer mechanism to be confirmed.]

7. How long we keep it

We keep personal information only as long as needed for the purposes above and to meet legal, tax and accounting requirements. Our default is to retain a delivered dossier and its client data for 24 months after the trip, then securely delete or anonymise it, unless the client instructs earlier deletion or a longer period is legally required.

8. How we protect it

We use administrative, technical and physical safeguards appropriate to the sensitivity of the information, including access controls, encryption in transit, limited access on a need-to-know basis, and secure disposal. No system is perfectly secure, but we work to protect information against loss and unauthorised access, use or disclosure. [Specific safeguards, for example device encryption, MFA and secure delivery, to be described.]

9. Your rights

Depending on where you live, you may have the right to: access your personal information and know how it is used and shared; request correction of inaccurate information; request deletion; withdraw consent; and, under the GDPR/UK GDPR, request restriction, portability, or object to certain processing. You may also complain to a regulator: the Office of the Privacy Commissioner of Canada, the UK ICO, or your EU supervisory authority. We will respond to verified requests within the time required by law.

10. Children

Our Services are directed to organisations and business travellers and are not intended for children. We do not knowingly collect personal information from children.

11. Changes

We may update this Policy from time to time. The effective date above shows the current version, and we will make the latest version available to clients.

12. Contact us

Questions or privacy requests can be directed to our Privacy Officer at The Advance Brief:

briefings@theadvancebrief.com
200 Broadway Street, Suite 1004, Tillsonburg, Ontario, N4G 5A7, Canada